# Grokking works in debugger but differs in Logstash

**URL:** <https://discuss.elastic.co/t/grokking-works-in-debugger-but-differs-in-logstash/196793>\
**Category:** Logstash\
**Created:** [August 26, 2019, 2:22pm UTC](https://discuss.elastic.co/t/grokking-works-in-debugger-but-differs-in-logstash/196793 "2019-08-26T14:22:20Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 26, 2019, 2:36pm UTC](https://discuss.elastic.co/t/grokking-works-in-debugger-but-differs-in-logstash/196793/2 "2019-08-26T14:36:03Z")

</div>

> [@naveenrt23](#):
>
> Does anyone know why there's a difference running locally vs using debuggers?

They are different code bases supported by different organizations. I would not expect them to stay in sync.

If you want to test grok filters then I would recommend that you do it using grok. Use two windows. In one run logstash with -r on the command line, so that it restarts the pipeline every time the configuration is modified. In the other edit the configuration. I would start with something like either

```
input { generator { count => 1 lines => ['/list/Lighter-test-group/xyz/123', "/list"] } }
filter {
    grok { match => { "message" => "..." } }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

or

```
input { file { path => "/home/foo.txt" sincedb_path => "/dev/null" start_position => beginning }
filter {
    grok { match => { "message" => "..." } }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

---

_[View the full topic](https://discuss.elastic.co/t/grokking-works-in-debugger-but-differs-in-logstash/196793)._
